Catch configuration drift against an as-built baseline

applied · 50 min · Objective 2.7

Task

Capture an as-built record of lin-srv in a form a machine can compare -- packages, enabled services, listening ports, users and key configuration files -- make a few undocumented changes, and then find every one of them by comparing a second capture against the first. This is configuration drift detection with nothing but standard tools.

Steps

  1. Write lab/drift/capture.sh that saves to a folder named on its command line: the sorted package list, systemctl list-unit-files --state=enabled, ss -tlnp, the list of user accounts from /etc/passwd, and sha256sum of /etc/ssh/sshd_config, /etc/fstab and /etc/hosts.
  2. Run it into lab/drift/as-built/.
  3. Make four undocumented changes: install a package, enable a service, add a user, and edit /etc/hosts. Record them in lab/drift/actual-changes.txt but do not look at that file again yet.
  4. Run the capture into lab/drift/now/ and save diff -r lab/drift/as-built lab/drift/now to lab/drift/diff.txt.
  5. List each change the diff reveals in lab/drift/found.csv with header area,change, then compare it with your record of actual changes.

Verify

These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.

ls lab/drift/as-built lab/drift/now | grep -c .
grep -Ec '^[<>]' lab/drift/diff.txt
awk -F, 'NR>1 {print $1}' lab/drift/found.csv | sort -u
awk -F, 'NR>1 {n++} END {print n" change(s) found"; exit (n<4)}' lab/drift/found.csv

The diff contains added or removed lines, and your found list covers packages, services, users and a configuration file checksum -- all four changes -- so the last command exits zero. A change the capture could not see means the capture is missing an area, and that is what to add before trusting it.

Notes

Configuration management tools such as Ansible, Puppet and DSC do this continuously and can put a drifted server back automatically. The capture here is the same idea at its smallest.

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.